Trezor's email provider breached, phishing emails sent to customers
Security & Exploits ·
Hardware wallet maker Trezor took down a compromised domain after attackers used a breached third-party email provider to send fake security alerts to its users.
Trezor said its third-party email provider was breached, allowing attackers to send messages from what appeared to be a legitimate company domain, according to Decrypt. The company has since shut down the affected domain and is investigating how the intruders gained access to it.
The phishing email, titled "Critical Security Alert: STM32 Entropy Vulnerability," falsely claimed a hardware flaw could expose users' recovery phrases, a tactic detailed by The Block. Trezor confirmed the message did not originate from the company and urged users not to click any links contained in it.
The incident traces back further than the email system itself. Reporting from WuBlockchain links the phishing campaign to an earlier breach at shipping provider ShipMonk, a third party that had handled customer shipments and exposed personal information later used to target Trezor customers directly.
Because recovery phrases, if exposed, would give attackers direct access to funds stored in a hardware wallet, the impersonation attempt carried significant risk despite requiring no compromise of Trezor's actual hardware or firmware. The company's response was limited to taking the domain offline and warning users, rather than announcing findings from its investigation into the access itself.
It remains unclear how the attackers obtained credentials to Trezor's legitimate domain through the email provider, whether any users clicked the phishing links or entered recovery information, and what connection, if any, exists between the ShipMonk data exposure and the more recent email provider breach. Trezor's investigation into the intrusion is ongoing, and no timeline for its conclusion has been given.